GMP & GDP Audits · 7 min read
Data Integrity in GMP Audits: Applying ALCOA+
A senior QP guide to data integrity GMP audits: applying ALCOA+, testing audit trails and access, and closing the findings inspectors look for.
By Balasubramanian Ramaiah · 9 June 2026 · Updated 17 September 2026

Data integrity GMP failures remain one of the most common reasons UK and EU regulators escalate findings, withhold certification or trigger product recalls. For pharma, biotech, CMO and importer quality teams, a defensible audit programme now depends as much on how records are generated, reviewed and retained as on the physical process itself. This article sets out how to apply the ALCOA+ principles during GMP audits so that data weaknesses are found before an inspector finds them.

Why data integrity GMP failures dominate inspection findings
Regulators including the MHRA and the FDA have made it clear that data governance is a board-level responsibility, not a back-office detail. The MHRA's 'GXP' Data Integrity Guidance and Definitions and EU GMP Annex 11 (computerised systems) and Chapter 4 (documentation) frame the expectations, while ICH Q9 (Quality Risk Management) and Q10 (Pharmaceutical Quality System) provide the risk and governance backbone. In US-facing supply chains, 21 CFR Parts 210 and 211 carry equivalent weight.
The recurring theme is that data integrity is a culture as much as a control set. An audit that only checks whether SOPs exist, without testing whether records are complete, contemporaneous and attributable, will miss the very behaviours that lead to data integrity citations: shared logins, uncontrolled spreadsheets, disabled audit trails and "testing into compliance".
The ALCOA+ principles, decoded for auditors
ALCOA was originally articulated by the FDA and later expanded to ALCOA+ to reflect modern, largely electronic, data environments. Each principle maps to specific evidence an auditor should request.
- Attributable — who performed the action and when. Look for unique user accounts, no shared credentials, and second-person review signatures.
- Legible — records are readable and permanent. Challenge correction-fluid use on paper and free-text fields that obscure original entries.
- Contemporaneous — recorded at the time of the activity. Compare timestamps against batch flow and shift patterns.
- Original — the first capture, or a verified true copy. Identify where the "raw data" actually lives, especially for instruments with local storage.
- Accurate — free from errors, with documented corrections. Review change reasons rather than just the changed values.
The "+" extends this to data being Complete, Consistent, Enduring and Available throughout the defined retention period. In practice the "+" attributes are where most contract and importer sites struggle, because data is spread across instruments, LIMS, ERP and the quality management system.
Paper, hybrid and fully electronic records
Most sites operate hybrid systems, and these carry the highest risk. A printout signed by an analyst is not the original record if the instrument retains the underlying electronic data and audit trail. During an audit, establish for each critical record whether the true raw data is paper, electronic, or both, and confirm the controls match.
Applying ALCOA+ during a GMP audit, step by step
Effective auditing of data integrity GMP controls is investigative, not tick-box. A structured approach keeps it proportionate and risk-based, in line with ICH Q9.
- Map the data lifecycle. For each critical quality decision, trace generation, processing, review, reporting, retention and disposal. The audit follows the data, not the org chart.
- Risk-rank systems and records. Prioritise systems that directly support batch release: chromatography data systems, balances, environmental monitoring, LIMS and the QMS.
- Interrogate audit trails. Confirm they are enabled, cannot be disabled by users, and are reviewed. Ask to see the audit trail review record, not just the SOP.
- Test access and segregation of duties. Verify that analysts cannot grant themselves administrator rights or delete data, and that system administration sits outside the testing function.
- Sample for the anomalies. Look for orphan data, aborted runs, re-integrations, out-of-sequence injections and gaps in sequential numbering.
If an audit trail is switched off, reviewed by no one, or the analyst holds administrator rights, you have a data integrity finding regardless of whether falsification has occurred. The absence of control is the deficiency.
Common data integrity findings and how to close them
Across GMP and GDP operations, the same weaknesses appear repeatedly. The most frequent include shared or generic logins, audit trails that are present but never reviewed, uncontrolled Excel calculations used for release decisions, and instruments where date and time settings can be altered by operators. On the distribution side, temperature monitoring data and its review trail are a growing focus under GDP guidelines.
Building durable corrective actions
Sustainable remediation pairs technical and behavioural controls. Technical fixes include enforced unique logins, locked system clocks, validated electronic workflows and routine audit trail review built into the batch record. Behavioural and governance measures, drawn from ICH Q10, include a data governance policy, an open reporting culture, periodic data integrity assessments and management review that treats data integrity as a quality metric. Annex 1's emphasis on contamination control reinforces the same point: monitoring data is only meaningful if it is trustworthy. Our published case studies show how layered controls hold up under inspection, and the wider range of services we provide is designed to embed these controls into day-to-day operations.
Embedding data integrity GMP readiness across the supply chain
Data integrity cannot stop at your own gate. Importers and marketing authorisation holders rely on data generated by contract manufacturers and laboratories, so supplier qualification and technical agreements must define who owns the raw data, how audit trails are reviewed and how records are made available during inspection. Treating data integrity as a shared, auditable responsibility, supported by a competent QP or RP, is what turns a one-off remediation into lasting compliance.
Key takeaways
- Audit the data lifecycle, not just the documentation, and let risk under ICH Q9 set your depth.
- Use ALCOA+ as your evidence checklist, paying particular attention to the "+" attributes across hybrid systems.
- Audit-trail review, access control and segregation of duties are where most findings are won or lost.
- Extend the same scrutiny to suppliers, CMOs and distribution partners through agreements and qualification.
If you want an independent, inspection-ready view of your data integrity GMP controls, our team can plan and deliver a focused GMP data integrity audit against MHRA and EU GMP expectations. Contact our QP team to discuss your sites, systems and timelines, and we will tailor the scope to your risk profile.
Regulatory sources
This guidance reflects current UK and EU GMP/GDP requirements. Primary references:
- EU GMP Annex 11 — Computerised Systems
- EudraLex Volume 4 — EU GMP Guidelines
- EU GMP Chapter 9 — Self Inspection
- MHRA Inspectorate Blog
Always confirm against the latest published version of each source.
Frequently asked questions
What does ALCOA+ stand for in GMP data integrity?+
ALCOA stands for Attributable, Legible, Contemporaneous, Original and Accurate, the core attributes of trustworthy data. The "+" adds Complete, Consistent, Enduring and Available, reflecting modern electronic and hybrid record environments. Together they form the benchmark the MHRA and EU GMP use to assess whether records can be relied upon for batch release decisions.
How is a data integrity audit different from a standard GMP audit?+
A standard GMP audit often focuses on processes, facilities and documentation existence. A data integrity audit follows the data lifecycle, interrogating audit trails, user access, timestamps and raw-data location to test whether records are genuine and complete. It is investigative and risk-based, drawing on ICH Q9, and frequently uncovers issues such as shared logins, disabled audit trails or uncontrolled spreadsheets.
Do data integrity expectations apply to GDP and distribution as well as manufacturing?+
Yes. EU and MHRA data integrity guidance applies across GxP, including good distribution practice. For distribution, common focus areas include temperature monitoring records, their review trails, and the controls around computerised systems used by wholesale dealers. Importers and marketing authorisation holders should also ensure supplier agreements define raw-data ownership and availability.